Junglewise Threat Intelligence

CVE-2026-47383: NocoDB stored XSS in row comments

CVE-2026-47383 · Severity: high · CVSS 4 · Published 2026-06-23

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB, a platform that turns databases into smart spreadsheets, was vulnerable to a security flaw where malicious users could embed hidden scripts in row comments. When another user hovers over these comments, the script automatically executes in their browser. This could allow an attacker to steal login tokens or perform unauthorized actions on behalf of other users, potentially compromising sensitive database information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability existed in NocoDB's row comment feature due to a lack of server-side sanitization. While the client-side editor attempted to strip script tags, the raw comment body was persisted and later rendered in the expanded-form sidebar. Specifically, the application passed the comment data to the Tippy library's 'data-tooltip' attribute with 'allowHTML: true' enabled. An authenticated attacker with comment permissions could inject attribute-level payloads that execute when a victim hovers over the comment. This allows for the theft of authentication JWTs from localStorage. The issue is resolved in version 2026.05.1.

Affected products

  • nocodb nocodb < 2026.05.1

Timeline

  • 2026-06-04: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD
  • 2026-05-01: patched: Approximate date based on version number 2026.05.1

References

Related threats